Masquerading as a default local account
Synopsis
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
1 Day
Required Data
Requires one of the following data sources: Windows Event Collector OR XDR Agent with eXtended Threat Hunting (XTH)
Detection Modules
Identity Analytics
ATT&CK Tactic
Stealth (TA0005), Persistence (TA0003)
ATT&CK Technique
Hide Artifacts: Hidden Users (T1564.002), Valid Accounts: Default Accounts (T1078.001), Masquerading (T1036)
Severity
Low
Description
A user created a new local account with the name of a default local account, such as Guest and DefaultAccount. An attacker may create a user with these known names to evade detection.
Attacker's Goals
An attacker is attempting to evade detection.
Investigative actions
Check what rights and permissions were granted to the new user.
Verify the action with the user who created the new account.
Follow actions and activities of the newly created default account.
Monitor the addition of the user to different groups.
Variations
Was this helpful?
